Storm Cloud is an espionage threat actor tied to Chinese intelligence, targeting Tibetan organizations across Asia.
Analyst brief
Storm Cloud is an espionage threat actor associated with Chinese intelligence. It primarily targets Tibetan organizations and individuals across Asia. Key TTPs include multi-platform malware families like GIMMICK and GOSLU, leveraging public cloud services such as Google Drive for C2 channels. Defenders should focus on monitoring anomalous cloud storage traffic, particularly suspicious activities related to Google Drive APIs.
Storm Cloud
unknown
Storm Cloud is a Chinese espionage threat actor known for targeting organizations across Asia, particularly Tibetan organizations and individuals. They use a variety of malware families, including GIMMICK and GOSLU, which are feature-rich and multi-platform. Storm Cloud leverages public cloud hosting services like Google Drive for command-and-control channels, making it difficult to detect their activities.